Hiring.Camp

Director, Information Security

Centric Brands

·

4 days ago

Location
Greensboro, NC, US
Workplace
Remote, Hybrid, Onsite
Type
Full-time
Department
IT
Seniority
Director
Closing date
Today
Source
iCIMS

Description

About Us

 

Centric Brands is a leading lifestyle brand collective that designs, sources, markets and sells high quality products in multiple segments, including women’s, men’s and kid’s apparel, accessories, entertainment and beauty. Centric Brands is focused on our customers and our brands that will drive the company’s future growth. We are defined by innovation as we seize new opportunities and thrive in an environment informed by creativity and thinking that is both analytical and outside the box. Centric Brands reflects a team built on respect, for others and for the hard work it takes to achieve our goals and build our bright future together.

Specific Responsibilities Would Include

Position Overview The Director of Information Security is responsible for developing and executing Centric Brands' enterprise cybersecurity strategy, protecting company information assets, and reducing cyber risk across the global business. This role leads security operations, governance, compliance, incident response, and emerging technology security programs while partnering with business and technology leaders to enable secure growth.   This position will be based in Greensboro, NC. It will follow a hybrid work schedule of Monday-Thursday in office with Friday being a remote work day. This schedule is subject to change based on business needs.Responsibilities

 

Strategy, Governance, and Executive Leadership • Provide strategic leadership for, and develop, implement, and operate, a company-wide information security program. • Advise senior leadership on security program direction and resource investment. • Develop and manage the information security budget, aligning investments with risk priorities. • Report regularly to executive leadership on security posture, risk reduction, incident readiness, and program maturity against defined KPIs. • Manage and facilitate global information security governance processes. • Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements. • Stay abreast of information security issues and regulatory changes affecting consumer goods, retail and trade at the state, national and global levels, participate in policy and practice discussions, and communicate to leadership on a regular basis about those topics. • Engage in professional development to maintain continual growth in professional skills and knowledge essential to the position.

 

Team Leadership • Mentor/Coach the Information Security Office team members and implement professional development plans for team members. Communicate clear goals and objectives. • Partner with infrastructure, network, cloud, application, and end-user computing teams to implement and maintain enterprise security standards and controls.

Policy, Compliance, and Audit • Lead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation. • Coordinate and track all information technology and security related audits including scope of audits, timelines, auditing agencies and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the company in its best light. • Provide guidance, evaluation and advocacy on audit responses. • Work with leadership and relevant responsible compliance department leadership to build cohesive security and compliance programs for the company to effectively address global statutory and regulatory requirements. • Develop a strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, PCI, CCPA, and GDPR. • Support Legal Discovery requests when required.

 

Security Awareness and Training • Work closely with IT leaders, technical experts and various leaders on a wide variety of security issues that require an in-depth understanding of the IT environment in their units. • Create education and awareness programs and advise operating units at all levels on security issues, best practices, and vulnerabilities. • Pursue employee-focused security initiatives addressing phishing, social engineering, and identity protection.

Incident Response and Resilience • Keep abreast of security incidents and act as primary control point during significant information security incidents. Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidents that arise. • Own and maintain the company’s incident response plan, including playbooks and regular tabletop exercises with business stakeholders. • Convene Ad Hoc Security Committee as appropriate and provide leadership for breach response and notification actions for the company. • Partner with IT and business leaders to develop and test business continuity, disaster recovery, and cyber resilience plans.

 

Risk Management and Third-Party Risk • Establish and oversee a third-party risk management program, including security assessments of vendors, licensing partners, and key service providers. • Provide leadership, direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies. • Support cyber insurance renewals, security questionnaires, and claims coordination.

 

Security Operations and Engineering • Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk. • Establish and oversee a vulnerability management program, including scanning, penetration testing, and remediation tracking. • Oversee day-to-day security operations, including MDR/SOC partner management, security monitoring and detection, threat intelligence, and endpoint and email security. • Set direction for cloud security posture and zero-trust architecture in partnership with infrastructure and application teams. • Establish governance for identity and access management, including privileged access controls and periodic access reviews. • Examine impacts of new technologies on the company’s overall information security. Establish processes to review implementation of new technologies to ensure security compliance. • Establish governance, risk management, and security standards for artificial intelligence (AI), generative AI, machine learning, and automation technologies. Partner with business and technology leaders to enable responsible and secure adoption of AI solutions across the enterprise.

Our Best Fit Candidate Would Have

Skills and Requirements

• Bachelor’s degree in Information Systems, Computer Science, or related field required. • CISSP, CISM, or equivalent security certification strongly preferred. • Minimum of 10 years’ experience in information security, including 5+ years leading security teams or programs. • Experience presenting security posture, risk, and program metrics to executive leadership. • Experience leading global security programs; retail, consumer goods, or manufacturing industry experience a plus. • Excellent communication skills - both written and verbal. • Exceptional, hands-on leader with a style that is engaging, innovative, and collaborative. • Ability to be flexible, work under pressure and tight deadlines. • Ability to travel as needed; once per quarter.• Ability and availability to work occasional nights and weekends. • Experience with Fortinet/FortiGate/Forticlient, Crowdstrike MDR/EDR, BitLocker, File Vault, MS Defender, and Azure Security services is a plus.

 

In return, we provide an industry-competitive salary, along with a comprehensive benefits plan (medical, dental, vision) that includes a matching 401(k), Summer Fridays, generous PTO, merchandise discounts, excellent career development opportunities, and a work environment that reflects our industry leadership. Our social impact program, Centric Cares, focuses on volunteerism to make a difference in communities we live and work in and our D&I committee is shaping the future of diversity, equity and inclusion at Centric Brands though workshops, resources and inspiring conversation.

 

At Centric Brands, we believe our people are our greatest asset, and we seek to structure competitive compensation offers to ensure that we are able to attract and retain the best talent. Our job postings include an annual base salary range at the time of employment. The stated base salary range represents our good faith estimate as to what candidates are likely to expect, and we tailor our offers within the range based on several factors, including the selected candidate's educational and professional experience, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the selection process. Base salary is a part of a total compensation package, which, depending on the position, may also include commission earnings, annual bonus and other Centric Brands sponsored benefit programs.

 

Be part of our growing community by getting involved with groups, teams and initiatives like Be Green, Be Giving, and Be Celebrated.

 

Centric Brands is an Equal Opportunity Employer

 

Please note that Centric Brands will only reach out to interview, make an offer of employment or conduct onboarding activities for candidates who have applied through our careers site. When interviewing for a position, the candidate experience will include live interaction, such as a video conference or telephone call, with a Recruiter and/or company employee(s). We will never ask for any money or payments from applicants at any point in the recruitment process. Be aware of suspicious recruitment activity. If you think you are a victim of an employment scam, you may contact your local law enforcement agency and/or visit the Federal Trade Commission website here: https://consumer.ftc.gov/articles/job-scams.

 

#LI-KW1

#LI-Hybrid

 

Skills

AzureMachine LearningCybersecurityPenetration TestingSOCRisk ManagementComplianceGDPRCISSP

Similar Jobs

30

Director, Information Security

Tera · 123 Front, Canada

4 days ago

Director Information Security

Akamai · Poland, PL · Remote

2 weeks ago

Information Security Director

Center Parcs Careers · Forest House, Forest House, Nottinghamshire, Newark, Nottinghamshire, United Kingdom

3 weeks ago

Director, Information Security

Trimedx · US IN Indianapolis - Central Office, United States of America

1 month ago

Information Security Director

Freemanhealth · 1102 W 32nd Street Freeman Hospital West, United States of America

1 month ago

Director, Information Security

UFCU · Austin, TX

2 months ago

Director, Information Security

Indigo Books & Music · Toronto, ON, Canada

2 months ago

Director Information Security

Bridgewater Bank · St Louis Park

2 months ago

Director, Information Security

whitecap · REMOTE GA 3 - Remotely Working in Georgia, United States of America · Hybrid, Remote

4 months ago

Director Information Security

American Express · Gurugram, HR, India · Hybrid

4 months ago

Director, Information Security

Brandeis University is · Brandeis - Waltham Campus, United States of America · Remote

5 months ago

Director, Information Security

Bdo · Toronto - Wellington St, Canada · Onsite

5 months ago

Director, Information Security

Whoop · Boston, MA · Onsite

5 months ago

Director - Information Security

Tdecu · Post Oak Corporate Office, United States of America

6 months ago

Director, Information Security

PetSmart Apply · Phoenix, AZ, US · Remote, Hybrid

1+ year ago

Director, Information Security - IFS Copperleaf

IFS · Vancouver, British Columbia, Canada · Hybrid

3 days ago

Director, Information Security - IFS Copperleaf

IFS · Vancouver, British Columbia, Canada · Hybrid

4 days ago

Senior Director, Information Security

Zillow · Bengaluru, India · Onsite

5 days ago

Director, Information Security & Technology

Gamechanger · GameChanger Remote - US · Remote

1 week ago

Director Information Security - GCC India & JAPAC

Regeneron · Hyderabad, India · Hybrid

1 week ago

Director, Information Security Office Consultant

Capitalone · McLean, VA, United States of America +2

2 weeks ago

Senior Director, Information Security Manager

0101022-GIA PROD US LOS ANGELES · Pittsburgh, PA, United States, US

3 weeks ago

Director, Information Security Operations

Mastercard · O'Fallon, Missouri (Main Campus), United States of America +2 · onsite

3 weeks ago

Director, Information Security (Security Engineering & Operations)

Achieve · Tempe, AZ, United States · Hybrid

3 weeks ago

Director, Information Security - Endpoint, Mobile, Cloud

Pru · Wash, 213 Washington St., Newark, NJ, United States of America

4 weeks ago

Director, Information Security - Assurance

Aveva · Cambridge - Science Park, United Kingdom +1

1 month ago

Director, Information Security - GRC

Aveva · Cambridge - Science Park, United Kingdom +1

1 month ago

Sr. Director Information Security

Viavisolutions · Chandler-HQ, AZ USA, United States of America +1

1 month ago

Associate Director, Information Security Risk

EQT Group · Stockholm, Stockholm, Sweden +1 · hybrid

1 month ago

Associate Director, Information Security Risk

EQT Group · Warszawa, Masovian Voivodeship, Poland · onsite

1 month ago